HIPAA compliance software that keeps PHI safeguards tracked and evidenced
If your product touches PHI, HIPAA applies the day your first BAA is signed. Complies tracks the administrative, physical, and technical safeguards as owned obligations, not a binder.
HIPAA compliance software tracks the safeguards the law requires around protected health information: Complies maps the Security Rule's administrative, physical, and technical safeguards to your actual controls, keeps business associate agreements signed and current, and collects the evidence that proves the safeguards operate. HIPAA is three rules working together: the Privacy Rule governs how PHI is used and disclosed, the Security Rule (164.308, 164.310, 164.312) demands documented safeguards for electronic PHI starting with a risk analysis, and the Breach Notification Rule requires notifying affected individuals, and HHS, when unsecured PHI is breached. For a healthtech startup, that means signed BAAs with every vendor touching PHI, access controls and audit logging on systems holding it, encryption, workforce training, and written policies. Complies turns each safeguard into an obligation with an owner and a due date, pulls technical evidence from AWS, Okta, and Google Workspace, and drafts policy starting points your team approves. There is no official HIPAA certification, which makes a defensible, documented posture the real goal. HIPAA safeguards overlap heavily with SOC 2 and ISO 27001, so work done there pre-fills your HIPAA map, and Growth at $199 a month includes the cross-mapping.
Complies handles it with policy management software and compliance evidence collection, with every control cross-mapped to the other frameworks you run.
What HIPAA asks of you, in plain language
| Code | What it demands | How Complies helps |
|---|---|---|
| 164.308(a)(1) | Conduct and document a risk analysis covering all ePHI | The risk register generates the risk analysis HHS asks for first in any investigation: threats, likelihood, impact, and treatment, each with an owner and a review date. |
| 164.312(a) | Control technical access to systems that hold ePHI | Maps SSO, IAM, and unique user IDs to the access control standard, schedules access reviews, and flags shared or orphaned accounts on PHI systems. |
| 164.312(b) | Record and examine activity in systems containing ePHI | Collects audit logging configuration and log review evidence from AWS on a schedule, so the audit controls standard proves itself continuously. |
| 164.308(b) | Hold business associate agreements with every vendor touching PHI | Tracks which vendors receive PHI, stores each signed BAA as evidence with a renewal date, and flags new integrations that lack one. |
| 164.404 | Notify affected individuals of breaches of unsecured PHI | Keeps the breach response plan, notification templates, and HHS reporting steps approved in advance, and logs incident timelines as evidence of the process. |
Collect once, comply many times
The Security Rule is mostly the same engineering work the other frameworks ask for: 164.312(a) access control matches SOC 2 CC6.1, ISO 27001 A.5.15, and GDPR Art. 32; the 164.308(a)(1) risk analysis matches SOC 2 CC3.2 and ISO Clause 6.1.2; audit logging matches PCI DSS Req. 10. What HIPAA adds is PHI-specific: BAAs, minimum necessary use, and breach notification to individuals and HHS. Complies maps shared controls once, marks them satisfied across frameworks, and isolates the genuinely HIPAA-only work, so a SOC 2-ready healthtech team sees most of its HIPAA map pre-filled.
| Control area | HIPAA | Also satisfies |
|---|---|---|
| Access control | 164.312(a) | SOC 2 CC6.1 · ISO A.5.15 · GDPR Art. 32 · PCI Req. 7 |
| Risk analysis | 164.308(a)(1) | SOC 2 CC3.2 · ISO Clause 6.1.2 · PCI Req. 12.3 |
| Audit logging | 164.312(b) | SOC 2 CC7.2 · ISO A.8.15 · PCI Req. 10 |
| Vendor agreements | 164.308(b) | SOC 2 CC9.2 · ISO A.5.19 · GDPR Art. 28 |
See the full crosswalk on the control mapping software page.
Getting HIPAA ready with Complies
Map where PHI lives and connect your stack
Connect AWS, Okta, and Google Workspace, mark which systems store or transmit ePHI, and let Complies build the safeguard map across 164.308, 164.310, and 164.312.
Run the risk analysis and close the gaps
Work the risk register into the documented risk analysis HHS expects, sign missing BAAs, and approve the AI-drafted policies and training obligations Complies assigns to owners.
Keep safeguards evidenced, not just written
Access reviews, log checks, training refreshers, and BAA renewals land on the calendar with owners. The readiness score shows your defensible posture, and the export pack backs it up.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
HIPAA questions, answered
No, and neither does anyone else: HHS offers no official HIPAA certification, so any badge claiming it is marketing. Complies assists with compliance workflows: it is not legal advice, and it does not certify you or guarantee regulatory outcomes. Your auditor and regulators decide; Complies gets you ready, with a documented risk analysis, tracked safeguards, and evidence that they operate.
Almost certainly not; you are most likely a business associate, a vendor that creates, receives, or maintains PHI for a covered entity. That still puts the Security Rule and Breach Notification Rule on you directly, and every hospital deal will require a signed BAA. Complies tracks your obligations as a business associate, including the BAAs you in turn need from your own subcontractors.
Encryption is an addressable specification, not optional but risk-driven: you implement it where reasonable and appropriate, or document why an alternative works. In practice, encrypting ePHI in transit and at rest is the expected answer for a cloud product, and it also makes breached data "secured", which changes your notification duties. Complies collects your encryption settings from AWS as recurring evidence.
Very well. Access control, audit logging, risk analysis, and incident response are shared between the Security Rule and SOC 2 CC-series criteria, so controls you built for SOC 2 pre-fill the HIPAA map in Complies. What remains is PHI-specific: BAAs, minimum necessary policies, training, and breach notification. Healthtech buyers commonly ask for both, and one control library serves both audits.
Audit Evidence Examples: What Auditors Actually Ask For
GDPRGDPR Compliance Checklist: 12 Steps for Small and Mid-Size Companies
Start your HIPAA readiness today
Growth includes every framework, cross-mapped, at $199 a month.